Millions of people in the United States and Canada face exposure of their government ID data after IDScan confirmed a breach that removed driver’s license records and other identity numbers from its cloud systems. The Louisiana-based identity verification company acknowledged the incident in a notice on its website, marking the first time the firm publicly confirmed an intrusion.

IDScan said the stolen material includes individuals’ full names and driver’s license numbers, along with identity numbers from other government-issued documents such as passports. The company also noted it "received information" on or around September 1 about a claim that it had been hacked. The firm added that "though full access to the information required payment," it was publishing the notice to alert potentially affected people.

An independent cybersecurity journalist flagged a searchable database on the dark web that reportedly contained driver’s license records for more than 150 million people living in the United States and Canada, including license photos. That reporter said he verified the data by checking his own entry. The exposed cache reportedly included high-profile entries, among them the U.S. Secretary of Defense Pete Hegseth and a security researcher who also checked his record.

IDScan supplies document-checking services to a range of corporate customers, from entertainment venues to cannabis dispensaries, and holds itself out as a repository for large volumes of identity records. The company has not disclosed how many customers or individual records were accessed, but its public materials state it holds over 150 million driver’s license records.

The Pentagon said it was aware of the suspected breach, and the FBI is investigating. IDScan said its own inquiry remains active. The company declined to answer questions about whether extortion or a ransom demand accompanied the leak, and it has not provided a tally of affected individuals.

The immediate implications are clear: people whose documents were stored by IDScan now face increased risk of identity fraud, and organisations that rely on the service must assess whether their customer verification processes were compromised. Federal investigation and the company’s ongoing probe will determine the scale of exposure and whether additional data beyond license numbers and photos was taken.